Security Advisories

Coordinated vulnerability disclosures and public security notes related to my research on software and networked systems security.

ESA ASN1SCC

Coordinated disclosure

Vulnerabilities in ESA's ASN.1 compiler stack

ASN1SCC is ESA's open-source ASN.1 compiler used to generate code for embedded and space-oriented systems. This disclosure concerns vulnerabilities found while studying parser and compiler security in software supply chains for critical networked systems.

The CVE identifiers below are tracked through ESA's GitHub Security Advisories for ASN1SCC. Technical details will be kept aligned with the coordinated public advisory material.

ESA ASN1SCC Security Advisories

For a plain-language explanation of the issue and its supply-chain relevance, see ASN.1 Strikes Back.

This page intentionally avoids exploit details before public disclosure is complete. The goal is to keep an inspectable record of the research while respecting the coordinated disclosure process.

Public References